Agent Exposure Auditor

A governance instrument for checking what you actually gave your agent – before something else finds out for you.

The conversation around AI risk has mostly settled on the wrong villain. A model that reasons brilliantly but can’t touch anything is a thought experiment. An agent with modest reasoning and standing access to email, files, production systems, payment rails, and the ability to spin up more agents is a different kind of system entirely – and it’s the one already being deployed.

This tool exists to answer one question plainly: you built an agent – now what did you actually give it?

Paste the agent’s system prompt, tool definitions, permission configuration, or orchestration code into the field below. The engine reads it for sixteen governance dimensions: autonomy, tool privilege, human oversight, persistence, delegation, financial authority, credential exposure, prompt-injection resistance, and more, and returns a structured exposure profile: what the agent can do, where oversight is present or absent, and what could plausibly go wrong given the shape of what’s actually configured.

It does not return a grade. Governance isn’t pass/fail. It returns a profile, a set of findings with an explanation of why each one matters and what damage it could cause, a suggested fix for each, and also, where the pasted text simply doesn’t address a category one way or the other – an honest not stated, rather than a false clean bill of health.

Who this is for

Anyone accountable for an agent’s behavior before it ships: the person writing the system prompt, the team reviewing what an agent is authorized to do, or anyone building an internal governance record for autonomous systems rather than trusting a vendor’s own assurances.

On sovereignty and how this works

This runs entirely in your browser. There is no API call, no server, no third party in the loop – what you paste is analyzed on your own device and never transmitted anywhere. That’s a deliberate governance choice, not just a cost one: a tool meant to audit an agent’s boundaries shouldn’t itself require you to hand sensitive configuration, credentials, or proprietary system prompts to an external service. The analysis is rule-based and transparent, every finding traces back to a specific pattern matched in your own text, and the rule set itself can be inspected, not a black box you’re asked to trust.

Limits

This is a pattern-based first pass, not a runtime security audit and not a substitute for professional review. It cannot see how the agent behaves once deployed, what your infrastructure enforces independently of this text, or anything left unstated in what you pasted. Categories marked not stated are open questions, not clearance, treat them as a prompt for deeper review, whether that’s a human reader or a more thorough LLM-assisted analysis of the full agent context. Use this as the first filter in a governance process, not the last word in one.

Run the audit

Paste the agent’s system prompt, tool/function definitions, permission or policy config, and any orchestration code below. The engine reads it as text and reports on autonomy, tool privilege, persistence, delegation, and eleven other exposure dimensions.

Runs entirely in your browser. Nothing you paste is sent anywhere.

0 characters

Agent exposure profile

Findings

This is a pattern-based reading of the text you pasted, not a runtime security audit. It cannot see how the agent actually behaves in production, what your infrastructure enforces independently of this text, or anything left unstated. Treat it as a first pass, not a clearance.